Published:2017/07/07  Last Updated:2017/07/11

JVN#21369452
Installers of Lhaz and Lhaz+, and Self-Extracting Archives created by Lhaz or Lhaz+ may insecurely load Dynamic Link Libraries

Overview

Installers of Lhaz and Lhaz+, and Self-extracting archive files created by Lhaz or Lhaz+ may insecurely load Dynamic Link Libraries.

Products Affected

  • Installer of Lhaz version 2.4.0 and earlier - CVE-2017-2246
  • Self-extracting archive files created by Lhaz version 2.4.0 and earlier - CVE-2017-2247
  • Installer of Lhaz+ version 3.4.0 and earlier - CVE-2017-2248
  • Self-extracting archive files created by Lhaz+ version 3.4.0 and earlier - CVE-2017-2249

Description

Lhaz and Lhaz+ provided by Chitora soft contain the following vulnerabilities.

  • Installers of Lhaz and Lhaz+ insecurely load Dynamic Link Libraries (CWE-427) - CVE-2017-2246, CVE-2017-2248
    CVSS v3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Base Score: 7.8
    CVSS v2 AV:N/AC:M/Au:N/C:P/I:P/A:P Base Score: 6.8
  • Self-extracting archive files created by Lhaz or Lhaz+ insecurely load Dynamic Link Libraries (CWE-427) - CVE-2017-2247, CVE-2017-2249
    CVSS v3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Base Score: 7.8
    CVSS v2 AV:N/AC:M/Au:N/C:P/I:P/A:P Base Score: 6.8

Impact

  • Arbitrary code may be executed with the privilege of the user invoking the installer. - CVE-2017-2246, CVE-2017-2248
  • Arbitrary code may be executed with the privilege of the user invoking the self-extracting archive file. - CVE-2017-2247, CVE-2017-2249

Solution

Update the software
Update to the latest version according to the information provided by the developer.

Vendor Status

Vendor Status Last Update Vendor Notes
Chitora soft Vulnerable 2017/07/07 Chitora soft website

References

  1. Japan Vulnerability Notes JVNTA#91240916
    Insecure DLL Loading and Command Execution Issues on Many Windows Application Programs

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Eili Masami of Tachibana Lab. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2017-2246
CVE-2017-2247
CVE-2017-2248
CVE-2017-2249
JVN iPedia JVNDB-2017-000169

Update History

2017/07/11
Information under [Products Affected] was modified.